Level

Nubank

Lead Security Engineer - Vulnerability Management

AI in this role

Lead security engineer owning vulnerability management, detection, asset coverage, and remediation workflows.

github
vulnerability-managementcloud-securityappsecthreat-intelligenceautomation
About Nu

Nu serves more than 140 million customers, guided by a mission to fight complexity and empower people. The company has been leading an industry transformation through innovative products and human-centered services.

 

Proprietary technology and data at scale power Nu’s digital platform, built to promote financial access, advancement, and transparency. Its business model thrives on customer love and lower costs, feeding a flywheel of growth and profitability.

Visit our Institutional Page

About the role

As a Lead Security Engineer, you will operate as a technical leader within Vulnerability Management, owning complex and ambiguous problems that span multiple teams and business areas.

You will help evolve Nubank’s vulnerability management capabilities into a scalable, auditable and risk-driven program. This includes improving detection and asset coverage, strengthening ownership and remediation workflows, increasing automation, supporting regulatory and audit readiness, and enabling engineering teams to resolve vulnerabilities efficiently.

This role requires strong autonomy, deep security engineering expertise, sound judgment and the ability to influence stakeholders without relying on formal authority. The role is aligned with IC6 expectations: leading complex cross-functional initiatives, setting standards, making technical decisions and acting as a multiplier for the broader organization.

You can find more about Nubank Infosec here: https://blog.nubank.com.br/infosec-nubank-protecao-dados/

You will be responsible for

  • Lead initiatives that improve the end-to-end vulnerability management lifecycle, from discovery and prioritization through remediation, verification and closure.

  • Design and evolve scalable processes, controls, workflows and automations for vulnerability intake, enrichment, ownership resolution, prioritization and SLA tracking.

  • Drive improvements across vulnerability identification sources, including cloud and infrastructure scanners, GitHub security findings, offensive security assessments, bug bounty reports, external assessments and threat intelligence.

  • Partner with Engineering, AppSec, Cloud Security, Offensive Security, Risks and other stakeholders to remove blockers and drive timely remediation.

  • Provide technical guidance on complex vulnerabilities, including risk context, remediation options, compensating controls and residual risk.

  • Lead root-cause analysis for recurring findings, data-quality problems, ownership gaps and workflow failures.

  • Define and improve metrics, dashboards and reporting that enable risk-based prioritization and executive decision-making.

  • Support regulatory, audit and compliance activities by ensuring that processes, evidence and remediation records are complete and auditable.

  • Contribute to the evolution of VM architecture, tooling and integrations, reducing operational toil and technical debt using AI tools.

  • Mentor engineers, share knowledge and raise the technical and operational bar across the security organization.

  • Participate in hiring and help build a strong, diverse and collaborative security engineering team.

We are looking for a person who has

  • Significant experience in information security, security engineering, vulnerability management, application security, cloud security or a related discipline.

  • Deep understanding of vulnerability management principles, including risk-based prioritization, remediation processes, verification and SLAs.

  • Experience designing or operating security controls and processes at scale.

  • Experience integrating security tools, scanners, ticketing systems, asset inventories and reporting platforms.

  • Strong technical understanding of at least some of the following areas: cloud infrastructure, application security, source code security, container security, network security, operating systems, CI/CD, APIs and automation.

  • Ability to investigate complex findings, identify root causes and translate technical analysis into clear remediation guidance.

  • Proven experience leading complex, ambiguous, cross-functional initiatives with multiple stakeholders.

  • Strong communication skills, with the ability to influence engineers, technical leaders, risk teams and senior stakeholders.

  • Professional fluency in English, given the global scope of Nubank’s security organization.

Nice to Have:

  • Experience working in regulated environments or supporting audits and compliance programs.

  • Experience developing scripts, automations or integrations using a programming or scripting language.

  • Continuous Threat Exposure Management (CTEM) knowledge.

You’ll fit well if you

  • Take ownership of complex problems and move them forward with autonomy.

  • Are comfortable operating in ambiguity and creating structure where processes or solutions are not yet defined.

  • Challenge the status quo and look for simpler, more scalable and more efficient ways of working.

  • Balance technical rigor, risk reduction, operational reliability and developer experience.

  • Communicate clearly with different audiences and build alignment across teams.

  • Enjoy mentoring others and multiplying your impact through standards, documentation and knowledge sharing.

  • Care deeply about protecting customers and enabling the business to move quickly and safely.

Location for this opportunity (City, Country)

  • São Paulo, Brazil

  • Campinas, Brazil

  • Rio de Janeiro, Brazil

  • Belo Horizonte, Brazil

Benefits

  • Chance of earning equity at Nubank

  • Food/ Meal Card (Vale-Refeição and/or Vale Alimentação)

  • Public Transportation Commuting Benefit (Vale-Transporte)

  • NuCare – Psychological, Financial and Legal Assistance Program

  • Life Insurance

  • Medical Plan

  • Dental Plan

  • NuLanguage – Language Course Program

  • Nucleo - Our learning platform of courses

  • Extended Parental Leave

  • Daycare Allowance

  • Parental Consultancy

  • Work-from-home Allowance

  • Gym Partnerships

  • 30 days of paid vacation

  • Relocation Assistance Package, if applicable

Work Model for this Role

Hybrid 2-3 times/week: Our hybrid work model brings us to the office at least twice a week, on strategic days designed to maximize team connection and collaboration. For more details, visit https://building.nubank.com/nu-hybrid-work-model/

Our recruitment process may involve the use of artificial intelligence–enabled tools, such as automated interview transcription and analysis, to support the evaluation process. Artificial intelligence is not used to make final hiring decisions; all decisions are made by human reviewers.

To maintain a consistent and fair process for every candidate, Nu does not provide individualized technical feedback. See how our policy works here

How we rate this

Lead Security Engineer - Vulnerability Management at Nubank rates 10 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Vulnerability ManagementCloud SecurityAppsecThreat IntelligenceAutomationGithub

Questions you could be asked

  1. Tell me about a project where vulnerability management was part of your work. What did you do?
  2. Tell me about a project where cloud security was part of your work. What did you do?
  3. Tell me about a project where appsec was part of your work. What did you do?
  4. Tell me about a project where threat intelligence was part of your work. What did you do?
  5. Tell me about a project where automation was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Vulnerability Management, Cloud Security, Appsec, Threat Intelligence, and Automation. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new remote cybersecurity jobs by email

One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Nubank

More cybersecurity jobs

Related searches

Same AI level